Data breach at RCM vendor, Mercy Health alerts patients

August 3, 2020 8:52 pm

Social Shares

Patients received an alert from Mercy Health Lorain (Ohio) Hospital, notifying them that their protected health information potentially may have been exposed in a data breach that happened at a revenue cycle management vendor.

According to the alert, RCM Enterprise Services reportedly discovered that it had mailed medical invoices to patients that had incorrect information. The usual practice followed by the vendor includes sending invoices which have names, street addresses, cities, states and zip codes, but inadvertently they sent out invoices which listed names, street addresses, and Social Security numbers.

The breach happened between Aug. 14 and Oct. 16, RCM Enterprise Services reportedly mailed invoices with Social Security numbers to the patients. The company  since then has begun alerting hospitals and health systems whose patients may have been affected. 

No evidence has so far been found that patients’ Social Security numbers may have been misused. Credit and identity monitoring has been offered by RCM Enterprise Services to the patients, who have also been recommended to review their financial statements.

 Appointment Scheduling using Robotic Process Automation

Subscribe to Billing Paradise Newsletter

We respect your email privacy


Social Shares

Leave a Comment

Your email address will not be published. Required fields are marked *


Get paid Three times faster with our 24/7 medical billing services.

Work with medical billers who understand your EHR's billing process backwards and forwards

Avail Free RCM Audit Worth $2,000! Check out 19 different KPI reports that stops your cash flow.